Using personal data to train AI under India's DPDP Act
AI teams in India need a lawful basis for every piece of personal data a model learns from. Public data, research and consent each work differently under the DPDP Act and Rules.
Evidence-led writing on audit, compliance and cyber governance, from the people who build audit software.
AI teams in India need a lawful basis for every piece of personal data a model learns from. Public data, research and consent each work differently under the DPDP Act and Rules.
ISO 42001 asks you to assess how an AI system could affect people and society, not only your organisation. This worked example uses a CV-screening model.
Sample sizes for testing controls depend mainly on how often the control runs. Here are the sizes auditors commonly use, and how to handle an exception.
CERT-In's 2022 directions give most organisations in India six hours to report specified cyber incidents. That only works if the decision to report is made in the first hour.
India's DPDP Rules, 2025 phase in over 18 months. The Data Protection Board is already running; consent managers start in November 2026 and core obligations in May 2027.
The Digital Omnibus pushed the EU AI Act's high-risk rules to December 2027 and August 2028. Transparency duties did not move, and some already apply.
Since 11 September 2026, anyone placing software or connected products on the EU market must report exploited vulnerabilities and severe incidents within 24 hours. Here is the runbook.
Whether a finding is major or minor decides whether you get certified on schedule. The difference is about the management system, not the size of the mistake.
Every ISO 9001:2015 certificate must move to the 2026 edition by 30 September 2029. For certification bodies that means three years of transition audits to schedule, staff and evidence.
CSF 2.0 added Govern as a sixth function. It covers strategy, roles, policy, oversight and supply chain risk, and it is where most organisations have the least evidence.
Two PCI DSS v4 requirements target attacks that skim card data from payment pages in the browser. Here is what each asks for, who it applies to and what assessors want to see.
Under SEBI's Cybersecurity and Cyber Resilience Framework, regulated entities need cyber audits by CERT-In empanelled auditors, half-yearly or yearly depending on their category.